Amazon Cognito · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Amazon Cognito Identity Provider API
104 actions
104 updates
phrasing
extends
openapi/amazon-cognito-amazon-cognito-identity-provider-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Amazon Cognito's API. It is a proposal applied on top of the contract, not a document Amazon Cognito publishes.
What the actions change
x-apievangelist-phrasing
Targets 104 · first 16 shown; the file carries all of them
$.info
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AddCustomAttributes'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminAddUserToGroup'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminConfirmSignUp'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminCreateUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDeleteUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDeleteUserAttributes'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDisableProviderForUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDisableUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminEnableUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminForgetDevice'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminGetDevice'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminGetUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminInitiateAuth'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminLinkProviderForUser'].post
$.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminListDevices'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Amazon Cognito Identity Provider API
version: 1.0.0
extends: openapi/amazon-cognito-amazon-cognito-identity-provider-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 103
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AddCustomAttributes'].post
update:
x-apievangelist-phrasing:
intent: Add custom attributes to a user pool
effect: write
questions:
- How do I add a custom profile field like a loyalty tier to my Cognito user pool?
- Can new custom attributes be added to a user pool that already has users?
instructions:
- text: Add custom attributes {attributes} to user pool {user_pool_id}.
slots:
attributes: requestBody.CustomAttributes
user_pool_id: requestBody.UserPoolId
- text: Extend the schema of pool {user_pool_id} with new custom fields {attributes}.
slots:
user_pool_id: requestBody.UserPoolId
attributes: requestBody.CustomAttributes
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminAddUserToGroup'].post
update:
x-apievangelist-phrasing:
intent: Add a user to a group
effect: write
questions:
- How do I put an existing user into an admins group in my user pool?
- Can I grant a user a group's IAM role by adding them to that group?
instructions:
- text: Add user {username} to group {group} in user pool {user_pool_id}.
slots:
username: requestBody.Username
group: requestBody.GroupName
user_pool_id: requestBody.UserPoolId
- text: Make {username} a member of the {group} group in pool {user_pool_id}.
slots:
username: requestBody.Username
group: requestBody.GroupName
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminConfirmSignUp'].post
update:
x-apievangelist-phrasing:
intent: Confirm a user's sign-up as an administrator
effect: write
questions:
- Can an admin confirm a new user's registration without them entering a verification code?
- How do I manually approve a user stuck in unconfirmed status?
instructions:
- text: Confirm the sign-up for user {username} in pool {user_pool_id} as an admin.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: Mark unconfirmed user {username} in pool {user_pool_id} as confirmed without a code.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminCreateUser'].post
update:
x-apievangelist-phrasing:
intent: Create a new user as an administrator
effect: write
questions:
- How do I create a user account on someone's behalf and send them an invitation?
- Can I set a temporary password when an admin creates a user?
- Is there a way to create a user without sending the welcome message?
instructions:
- text: Create user {username} in user pool {user_pool_id} with attributes {attributes}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
attributes: requestBody.UserAttributes
- text: Invite new user {username} to pool {user_pool_id} with temporary password {temp_password}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
temp_password: requestBody.TemporaryPassword
- text: Admin-create {username} in pool {user_pool_id} and deliver the invite by {mediums}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
mediums: requestBody.DesiredDeliveryMediums
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDeleteUser'].post
update:
x-apievangelist-phrasing:
intent: Delete a user as an administrator
effect: destructive
questions:
- How can an admin permanently remove any user from a user pool?
- Can I delete a user account by username from the backend?
instructions:
- text: Delete user {username} from user pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: As an admin, permanently remove {username}'s account from pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDeleteUserAttributes'].post
update:
x-apievangelist-phrasing:
intent: Delete attributes from a user as an administrator
effect: destructive
questions:
- How does an admin clear a field like phone number from a specific user's profile?
- Can I remove several attributes from one user at once from the backend?
instructions:
- text: Delete attributes {attribute_names} from user {username} in pool {user_pool_id}.
slots:
attribute_names: requestBody.UserAttributeNames
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: As an admin, clear {attribute_names} off {username}'s profile in pool {user_pool_id}.
slots:
attribute_names: requestBody.UserAttributeNames
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDisableProviderForUser'].post
update:
x-apievangelist-phrasing:
intent: Unlink a federated user from a local user
effect: destructive
questions:
- How do I stop a federated user from signing in through the Cognito account they were linked to?
- Can I remove the link between a social login and a native user pool account?
instructions:
- text: Disable the external provider link for user {user} in pool {user_pool_id}.
slots:
user: requestBody.User
user_pool_id: requestBody.UserPoolId
- text: Unlink federated identity {user} from its linked account in user pool {user_pool_id}.
slots:
user: requestBody.User
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminDisableUser'].post
update:
x-apievangelist-phrasing:
intent: Disable a user account
effect: destructive
questions:
- How do I block a user from signing in without deleting their account?
- Can I suspend a user in a user pool and turn them back on later?
instructions:
- text: Disable user {username} in user pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: Suspend {username}'s sign-in access in pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminEnableUser'].post
update:
x-apievangelist-phrasing:
intent: Re-enable a disabled user
effect: write
questions:
- How do I restore sign-in for a user I previously disabled?
- Can a suspended Cognito user be reactivated?
instructions:
- text: Enable user {username} in user pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: Reactivate the disabled account {username} in pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminForgetDevice'].post
update:
x-apievangelist-phrasing:
intent: Forget a user's remembered device as an admin
effect: destructive
questions:
- How can an admin remove a remembered device from a user's account?
- Can I make a pool stop trusting one of a user's devices from the backend?
instructions:
- text: Forget device {device_key} for user {username} in pool {user_pool_id}.
slots:
device_key: requestBody.DeviceKey
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: As an admin, drop remembered device {device_key} from {username}'s account in pool {user_pool_id}.
slots:
device_key: requestBody.DeviceKey
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminGetDevice'].post
update:
x-apievangelist-phrasing:
intent: Get a user's device as an admin
effect: read
questions:
- How does an admin look up details of one specific device a user has signed in from?
- Can I see when a user's device was last authenticated from the backend?
instructions:
- text: Get device {device_key} for user {username} in pool {user_pool_id}.
slots:
device_key: requestBody.DeviceKey
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: As an admin, show the details of {username}'s device {device_key} in pool {user_pool_id}.
slots:
username: requestBody.Username
device_key: requestBody.DeviceKey
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminGetUser'].post
update:
x-apievangelist-phrasing:
intent: Look up a user by username as an admin
effect: read
questions:
- How do I fetch a user's attributes and account status by their username?
- Can an admin check whether a specific user is confirmed or enabled?
instructions:
- text: Get user {username} from user pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: Show the status, MFA settings and attributes for {username} in pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminInitiateAuth'].post
update:
x-apievangelist-phrasing:
intent: Start sign-in for a user from a backend server
effect: write
questions:
- How does my server-side app start authenticating a user with admin credentials?
- Which auth flows can a backend use to sign a user in with their username and password?
instructions:
- text: Start server-side authentication with flow {auth_flow} for app client {client_id} in pool {user_pool_id}.
slots:
auth_flow: requestBody.AuthFlow
client_id: requestBody.ClientId
user_pool_id: requestBody.UserPoolId
- text: Sign a user in from my backend to pool {user_pool_id} via client {client_id} using flow {auth_flow} and parameters {auth_params}.
slots:
user_pool_id: requestBody.UserPoolId
client_id: requestBody.ClientId
auth_flow: requestBody.AuthFlow
auth_params: requestBody.AuthParameters
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminLinkProviderForUser'].post
update:
x-apievangelist-phrasing:
intent: Link a federated identity to an existing user
effect: write
questions:
- How do I link a user's social login to their existing native Cognito account?
- Can a federated user sign in as an existing local user after linking?
instructions:
- text: Link external identity {source_user} to existing user {destination_user} in pool {user_pool_id}.
slots:
source_user: requestBody.SourceUser
destination_user: requestBody.DestinationUser
user_pool_id: requestBody.UserPoolId
- text: Connect federated login {source_user} with local account {destination_user} in user pool {user_pool_id}.
slots:
source_user: requestBody.SourceUser
destination_user: requestBody.DestinationUser
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminListDevices'].post
update:
x-apievangelist-phrasing:
intent: List a user's devices as an admin
effect: read
questions:
- How can an admin see every device a particular user has remembered?
- Can I page through a user's devices from the backend?
instructions:
- text: List the devices for user {username} in pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: As an admin, show up to {limit} of {username}'s remembered devices in pool {user_pool_id}.
slots:
limit: requestBody.Limit
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminListGroupsForUser'].post
update:
x-apievangelist-phrasing:
intent: List the groups a user belongs to
effect: read
questions:
- Which groups is a given user a member of in my user pool?
- How do I check a user's group memberships before changing their permissions?
instructions:
- text: List the groups user {username} belongs to in pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: Show {username}'s group memberships in user pool {user_pool_id}, {limit} per page.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
limit: requestBody.Limit
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminListUserAuthEvents'].post
update:
x-apievangelist-phrasing:
intent: View a user's sign-in history and risk events
effect: read
questions:
- How can I see a user's recent sign-in attempts and their risk ratings?
- Does Cognito keep an auth event history I can review for a suspicious account?
instructions:
- text: List the authentication events for user {username} in pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: Show the last {max} sign-in events and risk results for {username} in pool {user_pool_id}.
slots:
max: requestBody.MaxResults
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminRemoveUserFromGroup'].post
update:
x-apievangelist-phrasing:
intent: Remove a user from a group
effect: destructive
questions:
- How do I take a user out of a group in my user pool?
- Can I revoke a user's group-based role by removing their membership?
instructions:
- text: Remove user {username} from group {group} in pool {user_pool_id}.
slots:
username: requestBody.Username
group: requestBody.GroupName
user_pool_id: requestBody.UserPoolId
- text: Take {username} out of the {group} group in user pool {user_pool_id}.
slots:
username: requestBody.Username
group: requestBody.GroupName
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminResetUserPassword'].post
update:
x-apievangelist-phrasing:
intent: Force a password reset for a user
effect: write
questions:
- How does an admin invalidate a user's password and make them reset it with a code?
- Can I force a user to choose a new password at next sign-in?
instructions:
- text: Reset the password for user {username} in pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: Invalidate {username}'s current password in pool {user_pool_id} and send them a reset code.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminRespondToAuthChallenge'].post
update:
x-apievangelist-phrasing:
intent: Answer a sign-in challenge from a backend server
effect: write
questions:
- How does my server respond to an MFA or new-password challenge during admin sign-in?
- What do I send back when server-side authentication returns a challenge?
instructions:
- text: Respond to challenge {challenge} for client {client_id} in pool {user_pool_id} with {responses}.
slots:
challenge: requestBody.ChallengeName
client_id: requestBody.ClientId
user_pool_id: requestBody.UserPoolId
responses: requestBody.ChallengeResponses
- text: From my backend, answer the {challenge} challenge in session {session} for app client {client_id} in pool {user_pool_id}.
slots:
challenge: requestBody.ChallengeName
session: requestBody.Session
client_id: requestBody.ClientId
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminSetUserMFAPreference'].post
update:
x-apievangelist-phrasing:
intent: Set a user's MFA preference as an admin
effect: write
questions:
- How can an admin turn on authenticator app MFA for a specific user?
- Can I choose SMS as the preferred MFA method for someone else's account?
instructions:
- text: Set the MFA preference for user {username} in pool {user_pool_id} to SMS settings {sms}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
sms: requestBody.SMSMfaSettings
- text: As an admin, enable authenticator app MFA for {username} in pool {user_pool_id} with settings {totp}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
totp: requestBody.SoftwareTokenMfaSettings
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminSetUserPassword'].post
update:
x-apievangelist-phrasing:
intent: Set a user's password as an admin
effect: write
questions:
- How does an admin set a specific password for a user directly?
- Can I make an admin-set password permanent so the user is not forced to change it?
instructions:
- text: Set the password for user {username} in pool {user_pool_id} to {password}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
password: requestBody.Password
- text: 'Give {username} in pool {user_pool_id} the password {password}, permanent: {permanent}.'
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
password: requestBody.Password
permanent: requestBody.Permanent
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminSetUserSettings'].post
update:
x-apievangelist-phrasing:
intent: Set a user's legacy SMS MFA options as an admin
effect: write
questions:
- Is there an older admin endpoint for setting a user's SMS MFA delivery options?
- How do I configure the legacy MFAOptions for a specific user from the backend?
instructions:
- text: Set legacy MFA options {mfa_options} for user {username} in pool {user_pool_id}.
slots:
mfa_options: requestBody.MFAOptions
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: Using the older admin user settings call, apply MFAOptions {mfa_options} to {username} in pool {user_pool_id}.
slots:
mfa_options: requestBody.MFAOptions
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminUpdateAuthEventFeedback'].post
update:
x-apievangelist-phrasing:
intent: Mark a user's sign-in event as valid or invalid
effect: write
questions:
- How can an admin flag a risky sign-in event as legitimate or fraudulent?
- Can I give the adaptive authentication engine feedback on a specific user's auth event?
instructions:
- text: Mark auth event {event_id} for user {username} in pool {user_pool_id} as {feedback}.
slots:
event_id: requestBody.EventId
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
feedback: requestBody.FeedbackValue
- text: As an admin, report {username}'s sign-in event {event_id} in pool {user_pool_id} as {feedback}.
slots:
username: requestBody.Username
event_id: requestBody.EventId
user_pool_id: requestBody.UserPoolId
feedback: requestBody.FeedbackValue
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminUpdateDeviceStatus'].post
update:
x-apievangelist-phrasing:
intent: Change a user's device remembered status as an admin
effect: write
questions:
- How does an admin mark a user's device as remembered or not remembered?
- Can I stop remembering a user's device without forgetting it entirely?
instructions:
- text: Set device {device_key} for user {username} in pool {user_pool_id} to {status}.
slots:
device_key: requestBody.DeviceKey
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
status: requestBody.DeviceRememberedStatus
- text: As an admin, mark {username}'s device {device_key} in pool {user_pool_id} as not remembered.
slots:
username: requestBody.Username
device_key: requestBody.DeviceKey
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminUpdateUserAttributes'].post
update:
x-apievangelist-phrasing:
intent: Update a user's attributes as an admin
effect: write
questions:
- How does an admin change a user's email, name or custom attributes?
- Can I mark a user's email as verified when updating their profile from the backend?
instructions:
- text: Update attributes for user {username} in pool {user_pool_id} to {attributes}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
attributes: requestBody.UserAttributes
- text: As an admin, set {username}'s profile fields in pool {user_pool_id} to {attributes}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
attributes: requestBody.UserAttributes
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AdminUserGlobalSignOut'].post
update:
x-apievangelist-phrasing:
intent: Sign a user out of all devices as an admin
effect: destructive
questions:
- How can an admin sign a compromised user out everywhere by revoking their refresh tokens?
- Can I force a specific user to log out on every device?
instructions:
- text: Sign user {username} out of all sessions in pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
- text: As an admin, revoke every refresh token for {username} in user pool {user_pool_id}.
slots:
username: requestBody.Username
user_pool_id: requestBody.UserPoolId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.AssociateSoftwareToken'].post
update:
x-apievangelist-phrasing:
intent: Start setting up an authenticator app for MFA
effect: write
questions:
- How do I get the secret code a user scans into an authenticator app for TOTP MFA?
- Can I begin authenticator app enrollment during a sign-in session instead of with an access token?
instructions:
- text: Generate a TOTP secret to register an authenticator app for the user with access token {access_token}.
slots:
access_token: requestBody.AccessToken
- text: Start authenticator app MFA setup in sign-in session {session}.
slots:
session: requestBody.Session
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.ChangePassword'].post
update:
x-apievangelist-phrasing:
intent: Change the signed-in user's password
effect: write
questions:
- How does a signed-in user change their own password?
- Does a user need their old password to set a new one?
instructions:
- text: Change my password from {old_password} to {new_password} using access token {access_token}.
slots:
old_password: requestBody.PreviousPassword
new_password: requestBody.ProposedPassword
access_token: requestBody.AccessToken
- text: Replace the current user's password {old_password} with {new_password} (token {access_token}).
slots:
old_password: requestBody.PreviousPassword
new_password: requestBody.ProposedPassword
access_token: requestBody.AccessToken
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.ConfirmDevice'].post
update:
x-apievangelist-phrasing:
intent: Confirm and start tracking a new device
effect: write
questions:
- How does an app register a device so Cognito can remember it for the signed-in user?
- Can I give a friendly name to a device when confirming it?
instructions:
- text: Confirm device {device_key} for the user with access token {access_token}.
slots:
device_key: requestBody.DeviceKey
access_token: requestBody.AccessToken
- text: Start tracking device {device_key} as {device_name} for the signed-in user ({access_token}).
slots:
device_key: requestBody.DeviceKey
device_name: requestBody.DeviceName
access_token: requestBody.AccessToken
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.ConfirmForgotPassword'].post
update:
x-apievangelist-phrasing:
intent: Set a new password with a reset code
effect: write
questions:
- How does a user finish resetting a forgotten password with the code they received?
- What do I submit along with the confirmation code to complete a password reset?
instructions:
- text: Complete the password reset for {username} with code {code} and new password {password} via client {client_id}.
slots:
username: requestBody.Username
code: requestBody.ConfirmationCode
password: requestBody.Password
client_id: requestBody.ClientId
- text: Use reset code {code} to set {username}'s new password to {password} on app client {client_id}.
slots:
code: requestBody.ConfirmationCode
username: requestBody.Username
password: requestBody.Password
client_id: requestBody.ClientId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.ConfirmSignUp'].post
update:
x-apievangelist-phrasing:
intent: Confirm a self sign-up with a code
effect: write
questions:
- How does a new user confirm their registration with the code emailed or texted to them?
- Can confirming sign-up move an email alias from another account?
instructions:
- text: Confirm sign-up for {username} with code {code} on app client {client_id}.
slots:
username: requestBody.Username
code: requestBody.ConfirmationCode
client_id: requestBody.ClientId
- text: Verify new registration {username} using confirmation code {code} through client {client_id}.
slots:
username: requestBody.Username
code: requestBody.ConfirmationCode
client_id: requestBody.ClientId
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.CreateGroup'].post
update:
x-apievangelist-phrasing:
intent: Create a user group
effect: write
questions:
- How do I create a group like admins or editors in my user pool?
- Can I attach an IAM role and a precedence to a new group?
instructions:
- text: Create group {group} in user pool {user_pool_id}.
slots:
group: requestBody.GroupName
user_pool_id: requestBody.UserPoolId
- text: Add a new group {group} to pool {user_pool_id} with role {role_arn} and precedence {precedence}.
slots:
group: requestBody.GroupName
user_pool_id: requestBody.UserPoolId
role_arn: requestBody.RoleArn
precedence: requestBody.Precedence
method: generated
generated: '2026-10-01'
- target: $.paths['/#X-Amz-Target=AWSCognitoIdentityProviderService.CreateIdentityProvider'].post
update:
x-apievangelist-phrasing:
intent: Add a third-party identity provider to a user pool
effect: write
questions:
- How do I let users sign in to my user pool with SAML or an OIDC provider?
- Can I map attributes from an external identity provider onto user pool attributes?
instructions:
- text: Add identity provider {provider_name} of type {provider_type} to pool {user_pool_id} with details {details}.
slots:
provider_name: requestBody.ProviderName
provider_type: requestBody.ProviderType
user_pool_id: requestBody.UserPoolId
details: requestBody.ProviderDetails
- text: Set up {provider_type} federation called {provider_name} in pool {user_pool_id} using {details} and attribute mapping {mapping}.
slots:
provider_type: requestBody.ProviderType
provider_name: requestBody.ProviderName
user_pool_id: requestBody.UserPoolId
details: requestBody.ProviderDetails
mapping: requestBody.AttributeMapping
method: generated
generated: '2026-10-01'
# --- truncated at 32 KB (89 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/amazon-cognito/refs/heads/main/overlays/amazon-cognito-amazon-cognito-identity-provider-api-phrasing-overlay.yaml